ferm: don't filter input by interface but only by ip
This allows VMs to talk to the host (Closes #6251)
This commit is contained in:
parent
e7acd24479
commit
5dcff45f98
|
@ -65,7 +65,7 @@ table filter {
|
|||
proto icmp icmp-type echo-request ACCEPT;
|
||||
|
||||
# local services
|
||||
interface $DEV_WAN daddr $IP_WAN mod state state NEW {
|
||||
daddr $IP_WAN mod state state NEW {
|
||||
# DNS requests
|
||||
@if $DNS_ON_WAN proto (udp tcp) dport 53
|
||||
mod comment comment "DNS on WAN"
|
||||
|
|
Reference in New Issue